{"id":158458,"date":"2024-07-23T15:09:16","date_gmt":"2024-07-23T13:09:16","guid":{"rendered":"https:\/\/www.fma.gv.at\/?page_id=158458"},"modified":"2026-02-13T13:51:15","modified_gmt":"2026-02-13T12:51:15","slug":"dora-managing-of-ict-third-party-risk","status":"publish","type":"page","link":"https:\/\/www.fma.gv.at\/en\/cross-sectoral-topics\/dora\/dora-managing-of-ict-third-party-risk\/","title":{"rendered":"DORA \u2013 Managing of ICT third-party risk"},"content":{"rendered":"<?xml encoding=\"utf-8\" ?><div class=\"wp-block-cover\"><img loading=\"lazy\" decoding=\"async\" width=\"1700\" height=\"716\" class=\"wp-block-cover__image-background wp-image-50878\" alt=\"\" src=\"https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Cover-DORA-Webseite-1700x716-DORA-Management-des-IKT-Drittparteienrisikos.jpg\" data-object-fit=\"cover\" srcset=\"https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Cover-DORA-Webseite-1700x716-DORA-Management-des-IKT-Drittparteienrisikos.jpg 1700w, https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Cover-DORA-Webseite-1700x716-DORA-Management-des-IKT-Drittparteienrisikos-320x135.jpg 320w, https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Cover-DORA-Webseite-1700x716-DORA-Management-des-IKT-Drittparteienrisikos-640x270.jpg 640w, https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Cover-DORA-Webseite-1700x716-DORA-Management-des-IKT-Drittparteienrisikos-1536x647.jpg 1536w\" sizes=\"auto, (max-width: 1700px) 100vw, 1700px\" \/><span aria-hidden=\"true\" class=\"wp-block-cover__background has-background-dim\" style=\"background-color:#6d747d\"><\/span><div class=\"wp-block-cover__inner-container is-layout-constrained wp-block-cover-is-layout-constrained\">\n<p class=\"has-text-align-right has-medium-font-size wp-block-paragraph\"><strong>Managing of ICT third-party risk<\/strong><\/p>\n<\/div><\/div><div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div><p class=\"wp-block-paragraph\">Financial entities manage the third-party risk of information and communication technologies (ICT third-party risk) across the entire life cycle. The ICT third-party risk is the ICT-related risk that may arise in conjunction with the usage of ICT services that are provided by ICT third-party service providers or their subcontractors. <\/p><p class=\"wp-block-paragraph\">In addition to the requirement to operate a register of information about ICT third-party service providers, the rules cover the drawing up of a strategy for ICT third-party risk, about conducting of due diligence checks prior to using ICT services, the contents of contracts and exit strategies.<\/p><h2 class=\"wp-block-heading\">Register of Information<\/h2><p class=\"wp-block-paragraph\">The register contains information about all ICT services that are directly provided by ICT third-party service providers. Sub-outsourcings are also required to be listed that support ICT services, critical or important functions or a material part thereof.<\/p><p class=\"wp-block-paragraph\">Such registers of information are required to be submitted to the competent authorities in full at the latter&rsquo;s request.<\/p><p class=\"wp-block-paragraph\">The FMA requires the submission of a complete register of information pursuant to Article 28 (3) 4th subparagraph of the Regulation (EU) 2022\/2554 for classifying ICT third-party service providers that are critical for financial undertakings, or for confirming the classifications conducted by the ESAs in 2025 and for effective supervision of financial undertakings.<\/p><p class=\"wp-block-paragraph\">The register of information is required to take place either at individual entity level or at the highest level of consolidation of a group within the EU. The rules are defines in Article 3 of the European Supervisory Authorities (ESA) Decision (<a href=\"https:\/\/www.eiopa.europa.eu\/document\/download\/b6dddfe3-08ab-4982-a901-2e5530d650d9_en?filename=2.%20ESA%202024%2022%20Decision%20on%20reporting%20of%20information%20for%20CTPP%20designation.pdf\" target=\"_blank\" rel=\"noopener\" class=\"external\">ESA Decision of 8 November 2024 concerning the reporting by competent authorities to the ESAs of information necessary for the designation of critical ICT third party service providers in accordance with Article 31(1)(a) of Regulation (EU) 2022\/2554 &ndash; ESA 2024 22<\/a>).<\/p><p class=\"wp-block-paragraph\">The reference date for the data contained in the register of information is 31 December of the preceding year.<\/p><p class=\"wp-block-paragraph\">The submission to the FMA as the competent authority takes place from 16.02.2026 until 13.03.2026 via the Incoming Platform.<\/p><p class=\"wp-block-paragraph\">Please make use of the opportunity for testing already provided by the FMA to identify problems prior to the submission period. The submission will be rejected if the validation rules are not met. <\/p><p class=\"wp-block-paragraph\">The Excel template that is required to be used when submitting the register of information to the FMA, can be found here:<\/p><p class=\"wp-block-paragraph\"><a href=\"\/wp-content\/plugins\/dw-fma\/download.php?d=7244&nonce=0a50c0bdc8c06094\" class=\"internal single-document-reference piwik_download\">FMA_Template_RoI_1_4_DE (<span class=\"sr-only\">Format: <\/span>xlsx, <span class=\"sr-only\">Size: <\/span>3,8 MB, <span class=\"sr-only\">Language: <\/span>German)<\/a>\n\n\n\n<\/p><p class=\"wp-block-paragraph\"><a href=\"\/wp-content\/plugins\/dw-fma\/download.php?d=7245&nonce=929fbc94b771088a\" class=\"internal single-document-reference piwik_download\">FMA_Template_RoI_1_4_EN (<span class=\"sr-only\">Format: <\/span>xlsx, <span class=\"sr-only\">Size: <\/span>3,8 MB, <span class=\"sr-only\">Language: <\/span>English)<\/a>\n\n\n\n<\/p><p class=\"wp-block-paragraph\">The following file contains an overview of the full options of drop-down list boxes to assist you in filling out the template:<\/p><p class=\"wp-block-paragraph\"><a href=\"\/wp-content\/plugins\/dw-fma\/download.php?d=7260&nonce=bc5f72a4b7f2d89a\" class=\"internal single-document-reference piwik_download\">FMA_RoI_Template_Dropdown_inklusive_ItemCodes (<span class=\"sr-only\">Format: <\/span>xlsx, <span class=\"sr-only\">Size: <\/span>59,7 KB, <span class=\"sr-only\">Language: <\/span>German)<\/a>\n\n\n\n<\/p><p class=\"wp-block-paragraph\">Since 02.04.2025 it has also been possible to submit EBA codes (by copying them) instead of plain text in the FMA template. This also allows conversion from XBRL format into the template by directly copying the values, without using lookups or the VLOOKUP function.<\/p><p class=\"wp-block-paragraph\">The submitted information is used to identify critical ICT third-party service providers and are also used in the supervisory process, e.g. in conjunction with the reporting of major ICT-related incidents.<\/p><p class=\"wp-block-paragraph\">Furthermore, financial entities shall inform the competent authority in a timely manner about any planned contractual arrangement on the use of ICT services supporting critical or important functions as well as when a function has become critical or important.<\/p><h2 class=\"wp-block-heading\">Strategy for ICT third-party risk<\/h2><p class=\"wp-block-paragraph\">The management body shall adopt this strategy and regularly check risks that are identified in conjunction with the contracts for using ICT services for supporting critical or important functions. ICT concentration risk at enterprise level is also evaluated.<\/p><h2 class=\"wp-block-heading\">Due diligence<\/h2><p class=\"wp-block-paragraph\">Prior to the conclusion of contracts financial entities conduct comprehensive reviews of ICT third-party service providers. For example, contracts are only allowed to be concluded with service providers that observe adequate standards for information security.<\/p><h2 class=\"wp-block-heading\">Contractual agreements<\/h2><p class=\"wp-block-paragraph\">The minimum content of contracts, for example the termination rights or the notification requirements in the case of an intended change of location, are prescribed. For ICT services that include critical or important functions, additional elements apply, e.g. The services to be agreed upon during a transitional period until the change to another ICT third-party service provider or performing services in-house.<\/p><h2 class=\"wp-block-heading\">Exit strategies<\/h2><p class=\"wp-block-paragraph\">The objective is potentially getting out of contractual agreements, without interruption to business activities, and maintaining the continuity and quality of the services provided. Contingency measures, alternative solutions and transition plans are identified for this purpose. Furthermore, exit plans are also tested and regularly checked.<\/p><h2 class=\"wp-block-heading\" id=\"dora-management\">Questions and Answers<\/h2><div class=\"card\">  <div class=\"card-header\" id=\"heading-6a39a69ae600c\">    <h3 class=\"mb-0\">      <button class=\"btn btn-link btn-block text-left p-0 d-flex align-items-center justify-content-between\" type=\"button\" data-toggle=\"collapse\" data-target=\"#collapse-heading-6a39a69ae600c\" aria-expanded=\"false\" aria-controls=\"collapse-heading-6a39a69ae600c\">        <span>When are financial entities requested by the FMA to submit the complete register of information?<\/span>        <i class=\"fa-solid fa-chevron-down text-primary\" aria-hidden=\"true\"><\/i>      <\/button>    <\/h3>  <\/div>  <div id=\"collapse-heading-6a39a69ae600c\" class=\"collapse\" aria-labelledby=\"heading-6a39a69ae600c\">    <div class=\"card-body\"><p>The date for submitting the register of information in 2026 will be announced by the FMA and will be from 16.02.2026 until 13.03.2026.<\/p>\n<p>Competent authorities are required to submit registers of information to the ESAs by 31 March 2026.<\/p>\n<p>Regarding the level of consolidation for reporting, please refer to Article 3 of the <a href=\"https:\/\/www.esma.europa.eu\/sites\/default\/files\/2024-11\/ESA_2024_22_Decision_on_reporting_of_information_for_CTPP_designation.pdf\" class=\"external\" target=\"_blank\" rel=\"noopener\">Decision concerning the reporting by competent authorities to the ESAs of information necessary for the designation of critical ICT third party service providers<\/a>. You should also consult the <a href=\"https:\/\/www.eba.europa.eu\/sites\/default\/files\/2025-02\/5276b0df-4711-443f-a900-61b8a680ff67\/20250214%20-%20DORA%20RoI%20reporting%20FAQ.pdf\" class=\"external\" target=\"_blank\" rel=\"noopener\">ESA FAQ Reporting of registers of information (RoI) under DORA<\/a>; questions 4 to 9 are particularly relevant for issues relating to consolidation.<\/p>\n<p>Notes:<\/p>\n<ul>\n<li>In the case of Austrian groups, foreign subsidiaries in EU States are also to be included.<\/li>\n<li>Subsidiaries licensed in Austria that belong to groups established in other EU States submit their registers to the parent undertaking in the group, which then submits it to its competent authority. The FMA receives the registers of information from these subsidiaries directly from the ESAs.<\/li>\n<li>Only financial entities are to be included in the consolidation.<\/li>\n<li>Every financial entity is only listed once in the reports that are submitted to the ESAs.<\/li>\n<\/ul>    <\/div>  <\/div><\/div><div class=\"card\">  <div class=\"card-header\" id=\"dropdownvalue\">    <h3 class=\"mb-0\">      <button class=\"btn btn-link btn-block text-left p-0 d-flex align-items-center justify-content-between\" type=\"button\" data-toggle=\"collapse\" data-target=\"#collapse-dropdownvalue\" aria-expanded=\"false\" aria-controls=\"collapse-dropdownvalue\">        <span>Where can the values be found that may be entered in the drop-down list boxes in the template?<\/span>        <i class=\"fa-solid fa-chevron-down text-primary\" aria-hidden=\"true\"><\/i>      <\/button>    <\/h3>  <\/div>  <div id=\"collapse-dropdownvalue\" class=\"collapse\" aria-labelledby=\"dropdownvalue\">    <div class=\"card-body\"><p>An Excel file containing these lists can also be found on the FMA website:&nbsp;<a href=\"https:\/\/www.fma.gv.at\/wp-content\/plugins\/dw-fma\/download.php?d=7252&amp;nonce=190ac8c74e0c3a3a\">Link<\/a><\/p>    <\/div>  <\/div><\/div><div class=\"card\">  <div class=\"card-header\" id=\"nonlife\">    <h3 class=\"mb-0\">      <button class=\"btn btn-link btn-block text-left p-0 d-flex align-items-center justify-content-between\" type=\"button\" data-toggle=\"collapse\" data-target=\"#collapse-nonlife\" aria-expanded=\"false\" aria-controls=\"collapse-nonlife\">        <span>In the drop down list about licensed activities (B.06.02.0020) some sectors of non-life insurance (esp. legal protection) seem to be missing &ndash; what should be entered here?<\/span>        <i class=\"fa-solid fa-chevron-down text-primary\" aria-hidden=\"true\"><\/i>      <\/button>    <\/h3>  <\/div>  <div id=\"collapse-nonlife\" class=\"collapse\" aria-labelledby=\"nonlife\">    <div class=\"card-body\"><p>Where there are options missing, use the following catch-all category: &lsquo;Non-Life Insurance: All classes, at the choice of the Member States, which shall notify the other Member States and the Commission of their choice&rsquo;<\/p>    <\/div>  <\/div><\/div><div class=\"card\">  <div class=\"card-header\" id=\"intergroup\">    <h3 class=\"mb-0\">      <button class=\"btn btn-link btn-block text-left p-0 d-flex align-items-center justify-content-between\" type=\"button\" data-toggle=\"collapse\" data-target=\"#collapse-intergroup\" aria-expanded=\"false\" aria-controls=\"collapse-intergroup\">        <span>How should a service provider within the group and several external sub-service providers be entered in the register of service providers?<\/span>        <i class=\"fa-solid fa-chevron-down text-primary\" aria-hidden=\"true\"><\/i>      <\/button>    <\/h3>  <\/div>  <div id=\"collapse-intergroup\" class=\"collapse\" aria-labelledby=\"intergroup\">    <div class=\"card-body\"><p>In this case, not only do you need to fill out sheet B.05.02 (service supply chain), but information about the first external service in a chain must also be entered in sheets B.05.01 and B.07.01 (in the case of critical\/material functions).<\/p>    <\/div>  <\/div><\/div><div class=\"card\">  <div class=\"card-header\" id=\"thirdcountrynolei\">    <h3 class=\"mb-0\">      <button class=\"btn btn-link btn-block text-left p-0 d-flex align-items-center justify-content-between\" type=\"button\" data-toggle=\"collapse\" data-target=\"#collapse-thirdcountrynolei\" aria-expanded=\"false\" aria-controls=\"collapse-thirdcountrynolei\">        <span>An ICT service provider from a non-EU third country does not have an LEI code, what may be entered instead in this case?<\/span>        <i class=\"fa-solid fa-chevron-down text-primary\" aria-hidden=\"true\"><\/i>      <\/button>    <\/h3>  <\/div>  <div id=\"collapse-thirdcountrynolei\" class=\"collapse\" aria-labelledby=\"thirdcountrynolei\">    <div class=\"card-body\"><p>In this instance, a national code may be used as an exception (see&nbsp;<a href=\"https:\/\/www.eba.europa.eu\/sites\/default\/files\/2025-02\/5276b0df-4711-443f-a900-61b8a680ff67\/20250214%20-%20DORA%20RoI%20reporting%20FAQ.pdf\" class=\"external\" target=\"_blank\" rel=\"noopener\">EBA-FAQ<\/a>&nbsp;#40).<\/p>    <\/div>  <\/div><\/div><div class=\"card\">  <div class=\"card-header\" id=\"heading-6a39a69ae6415\">    <h3 class=\"mb-0\">      <button class=\"btn btn-link btn-block text-left p-0 d-flex align-items-center justify-content-between\" type=\"button\" data-toggle=\"collapse\" data-target=\"#collapse-heading-6a39a69ae6415\" aria-expanded=\"false\" aria-controls=\"collapse-heading-6a39a69ae6415\">        <span>How is a critical function defined?<\/span>        <i class=\"fa-solid fa-chevron-down text-primary\" aria-hidden=\"true\"><\/i>      <\/button>    <\/h3>  <\/div>  <div id=\"collapse-heading-6a39a69ae6415\" class=\"collapse\" aria-labelledby=\"heading-6a39a69ae6415\">    <div class=\"card-body\"><p>Article 3(22) DORA defines a critical function as follows:<\/p>\n<p>&ldquo;<em>a function, the disruption of which would materially impair the financial performance of a financial entity, or the soundness or continuity of its services and activities, or the discontinued, defective or failed performance of that function would materially impair the continuing compliance of a financial entity with the conditions and obligations of its authorisation, or with its other obligations under applicable financial services law;<\/em>&rdquo;<\/p>    <\/div>  <\/div><\/div><div class=\"card\">  <div class=\"card-header\" id=\"heading-6a39a69ae64f9\">    <h3 class=\"mb-0\">      <button class=\"btn btn-link btn-block text-left p-0 d-flex align-items-center justify-content-between\" type=\"button\" data-toggle=\"collapse\" data-target=\"#collapse-heading-6a39a69ae64f9\" aria-expanded=\"false\" aria-controls=\"collapse-heading-6a39a69ae64f9\">        <span>Do all rules also apply to the same extent for subsidiaries?<\/span>        <i class=\"fa-solid fa-chevron-down text-primary\" aria-hidden=\"true\"><\/i>      <\/button>    <\/h3>  <\/div>  <div id=\"collapse-heading-6a39a69ae64f9\" class=\"collapse\" aria-labelledby=\"heading-6a39a69ae64f9\">    <div class=\"card-body\"><p>If the subsidiary itself falls within DORA&rsquo;s scope of application (Article 2 DORA), then all rules apply shall apply to the same extent. Where aspects of the ICT service are for example are outsourced to the parent undertaking (or vice versa) then this triggers it being captured and treated as an internal ICT service provider.<\/p>    <\/div>  <\/div><\/div><div class=\"card\">  <div class=\"card-header\" id=\"heading-6a39a69ae65cc\">    <h3 class=\"mb-0\">      <button class=\"btn btn-link btn-block text-left p-0 d-flex align-items-center justify-content-between\" type=\"button\" data-toggle=\"collapse\" data-target=\"#collapse-heading-6a39a69ae65cc\" aria-expanded=\"false\" aria-controls=\"collapse-heading-6a39a69ae65cc\">        <span>Should only those ICT contracts be listed in Template RT.07.01 that contain ICT services that materially support a critical or important function?<\/span>        <i class=\"fa-solid fa-chevron-down text-primary\" aria-hidden=\"true\"><\/i>      <\/button>    <\/h3>  <\/div>  <div id=\"collapse-heading-6a39a69ae65cc\" class=\"collapse\" aria-labelledby=\"heading-6a39a69ae65cc\">    <div class=\"card-body\"><p>Yes. See also the question &ldquo;Which service providers support critical or important functions?&rdquo;<\/p>    <\/div>  <\/div><\/div><div class=\"card\">  <div class=\"card-header\" id=\"heading-6a39a69ae669c\">    <h3 class=\"mb-0\">      <button class=\"btn btn-link btn-block text-left p-0 d-flex align-items-center justify-content-between\" type=\"button\" data-toggle=\"collapse\" data-target=\"#collapse-heading-6a39a69ae669c\" aria-expanded=\"false\" aria-controls=\"collapse-heading-6a39a69ae669c\">        <span>Which service providers support critical or important functions?<\/span>        <i class=\"fa-solid fa-chevron-down text-primary\" aria-hidden=\"true\"><\/i>      <\/button>    <\/h3>  <\/div>  <div id=\"collapse-heading-6a39a69ae669c\" class=\"collapse\" aria-labelledby=\"heading-6a39a69ae669c\">    <div class=\"card-body\"><p>From the FMA&rsquo;s perspective a risk-based approach is necessary when classifying which service providers support critical or important functions. In line with <a href=\"https:\/\/www.eiopa.europa.eu\/qa-regulation\/questions-and-answers-database\/2750-dora006_en\" target=\"_blank\" rel=\"noopener\" class=\"external\">ESA Q&amp;A 2750<\/a> when classifying a service provider, the issue is relevant about whether the disruption of the system or service provider would materially impair the affected function(s) &ndash; especially regarding continuity and security.<\/p>    <\/div>  <\/div><\/div><div class=\"card\">  <div class=\"card-header\" id=\"heading-6a39a69ae6778\">    <h3 class=\"mb-0\">      <button class=\"btn btn-link btn-block text-left p-0 d-flex align-items-center justify-content-between\" type=\"button\" data-toggle=\"collapse\" data-target=\"#collapse-heading-6a39a69ae6778\" aria-expanded=\"false\" aria-controls=\"collapse-heading-6a39a69ae6778\">        <span>Can individual minimum requirements stated in Article 30 DORA be waived for certain contracts on the basis of the principle of proportionality?<\/span>        <i class=\"fa-solid fa-chevron-down text-primary\" aria-hidden=\"true\"><\/i>      <\/button>    <\/h3>  <\/div>  <div id=\"collapse-heading-6a39a69ae6778\" class=\"collapse\" aria-labelledby=\"heading-6a39a69ae6778\">    <div class=\"card-body\"><p>According to Article&nbsp;4 (2) DORA the principle of proportionality applies for Chapter III and IV, as where are Chapter V Section I, where stipulated in the relevant rules contained therein. Regarding Article 30(2) (i) DORA, reference is made to Article&nbsp;13 (6) DORA regarding the participation of ICT third-party service providers in the ICT security awareness programmes and digital operational resilience training. It stipulates that financial entities must include ICT third-party service providers as appropriate in their relevant training programmes. With regard to this rule, financial entities are therefore required to assess the appropriateness of the inclusion of ICT third-party service providers.<\/p>    <\/div>  <\/div><\/div><div class=\"card\">  <div class=\"card-header\" id=\"heading-6a39a69ae6852\">    <h3 class=\"mb-0\">      <button class=\"btn btn-link btn-block text-left p-0 d-flex align-items-center justify-content-between\" type=\"button\" data-toggle=\"collapse\" data-target=\"#collapse-heading-6a39a69ae6852\" aria-expanded=\"false\" aria-controls=\"collapse-heading-6a39a69ae6852\">        <span>Are purely advisory contracts in the ICT environment to generally be classified as ICT services where services are provided on a permanent or recurring basis?<\/span>        <i class=\"fa-solid fa-chevron-down text-primary\" aria-hidden=\"true\"><\/i>      <\/button>    <\/h3>  <\/div>  <div id=\"collapse-heading-6a39a69ae6852\" class=\"collapse\" aria-labelledby=\"heading-6a39a69ae6852\">    <div class=\"card-body\"><p>In Annex III of the Specification of the Register of Information, consulting contracts are stated as a separate category (explained as &lsquo;Provision of intellectual\/ICT expertise services&rsquo;). Such contracts would also need to be included in this context, provided that a clear link to ICT systems exists.<\/p>\n<p>Where it is clearly apparent from the contract that certain minimum contents of the contract pursuant to Article 30 (2) DORA are not applicable, then these must not be included as separate points in the contract (e.g. omission of the clause about the place of data processing where it is determined that no data is transferred to the consultant).<\/p>\n<p>Where a large amount of these minimum contents appear not to be applicable, this might also form an indication that the specific service is not related to Information and communication technologies (ICT systems).<\/p>    <\/div>  <\/div><\/div><div class=\"card\">  <div class=\"card-header\" id=\"heading-6a39a69ae6938\">    <h3 class=\"mb-0\">      <button class=\"btn btn-link btn-block text-left p-0 d-flex align-items-center justify-content-between\" type=\"button\" data-toggle=\"collapse\" data-target=\"#collapse-heading-6a39a69ae6938\" aria-expanded=\"false\" aria-controls=\"collapse-heading-6a39a69ae6938\">        <span>Does obtaining open source and freeware software fall under the term ICT services?<\/span>        <i class=\"fa-solid fa-chevron-down text-primary\" aria-hidden=\"true\"><\/i>      <\/button>    <\/h3>  <\/div>  <div id=\"collapse-heading-6a39a69ae6938\" class=\"collapse\" aria-labelledby=\"heading-6a39a69ae6938\">    <div class=\"card-body\"><p>Here it is necessary to consider how the open source software is obtained. Where other services are linked to it, such as for example ongoing support, advice or similar services, then an ICT service as defined in DORA may exist. If in an extreme case only open source code is obtained, e.g. from a repository, and then used within the entity, then no such service would exist; irrespective this other provisions in DORA (for example ICT systems acquisition, development, and maintenance) may apply accordingly.<\/p>    <\/div>  <\/div><\/div><div class=\"card\">  <div class=\"card-header\" id=\"heading-6a39a69ae6a21\">    <h3 class=\"mb-0\">      <button class=\"btn btn-link btn-block text-left p-0 d-flex align-items-center justify-content-between\" type=\"button\" data-toggle=\"collapse\" data-target=\"#collapse-heading-6a39a69ae6a21\" aria-expanded=\"false\" aria-controls=\"collapse-heading-6a39a69ae6a21\">        <span>What does the term &ldquo;assurance levels&rdquo; mean with regard to Article 30(3) (e) (ii) DORA, and how is the right &ldquo;to agree alternative assurance levels&rdquo; to be understood?<\/span>        <i class=\"fa-solid fa-chevron-down text-primary\" aria-hidden=\"true\"><\/i>      <\/button>    <\/h3>  <\/div>  <div id=\"collapse-heading-6a39a69ae6a21\" class=\"collapse\" aria-labelledby=\"heading-6a39a69ae6a21\">    <div class=\"card-body\"><p>Article&nbsp;30 (3) (e) (ii) DORA states that the contractual agreements on the usage of ICT services to support critical or important functions cover the right to monitor the ICT third-party service provider&rsquo;s service on a continual basis, including the right to agree on alternative assurance levels if other clients&rsquo; rights are affected.<\/p>\n<p>This paragraph must be read in conjunction with Article&nbsp;30 (3) (e) (i) DORA:<\/p>\n<p>&ldquo;<em>(i) unrestricted rights of access, inspection and audit by the financial entity, or an appointed third party, and by the competent authority, and the right to take copies of relevant documentation on-site if they are critical to the operations of the ICT third-party service provider, the effective exercise of which is not impeded or limited by other contractual arrangements or implementation policies;<\/em><\/p>\n<p><em>ii) the right to agree on alternative assurance levels if other clients&rsquo; rights are affected;<\/em>&rdquo;<\/p>\n<p>Therefore: in the event that &lsquo;traditional&rsquo; audit rights would encroach on the rights of other clients of the service provider due to the specific situation in question, alternative ways may be agreed upon to monitor the service provider&rsquo;s service.<\/p>    <\/div>  <\/div><\/div><div class=\"card\">  <div class=\"card-header\" id=\"heading-6a39a69ae6b01\">    <h3 class=\"mb-0\">      <button class=\"btn btn-link btn-block text-left p-0 d-flex align-items-center justify-content-between\" type=\"button\" data-toggle=\"collapse\" data-target=\"#collapse-heading-6a39a69ae6b01\" aria-expanded=\"false\" aria-controls=\"collapse-heading-6a39a69ae6b01\">        <span>How is the designation of a &ldquo;simple&rdquo; ICT service provider delineated in DORA?<\/span>        <i class=\"fa-solid fa-chevron-down text-primary\" aria-hidden=\"true\"><\/i>      <\/button>    <\/h3>  <\/div>  <div id=\"collapse-heading-6a39a69ae6b01\" class=\"collapse\" aria-labelledby=\"heading-6a39a69ae6b01\">    <div class=\"card-body\"><p>In relation to the filling of the register of information, the question also arises about whether there is a materiality limit regarding the &ldquo;supporting&rdquo; of critical functions. This question has been asked to the ESAs through the Q&amp;A process. There is no specific time frame in this regard, but clarification is expected at European level on this issue.<\/p>    <\/div>  <\/div><\/div><div class=\"card\">  <div class=\"card-header\" id=\"finvsictservices\">    <h3 class=\"mb-0\">      <button class=\"btn btn-link btn-block text-left p-0 d-flex align-items-center justify-content-between\" type=\"button\" data-toggle=\"collapse\" data-target=\"#collapse-finvsictservices\" aria-expanded=\"false\" aria-controls=\"collapse-finvsictservices\">        <span>Is there a differentiation under DORA of financial services and ICT services?<\/span>        <i class=\"fa-solid fa-chevron-down text-primary\" aria-hidden=\"true\"><\/i>      <\/button>    <\/h3>  <\/div>  <div id=\"collapse-finvsictservices\" class=\"collapse\" aria-labelledby=\"finvsictservices\">    <div class=\"card-body\"><p>See <a class=\"external\" href=\"https:\/\/www.eiopa.europa.eu\/qa-regulation\/questions-and-answers-database\/2999-dora030_en\" target=\"_blank\" rel=\"noopener\">DORA Q&amp;A 2999&nbsp;<span class=\"sr-only\">Link zu externer Seite. &Ouml;ffnet in neuem Fenster.<\/span><\/a>:<\/p>\n<p><em>The answer to this question is provided by the European Commission<\/em>.<\/p>\n<p>The definition of &lsquo;ICT services&rsquo; in Article 3(21) of Regulation (EU) 2022\/2554 intentionally maintains a broad scope. Recital (35) of Regulation (EU) 2022\/2554 indeed clarifies that, with the aim of maintaining a high level of digital operational resilience, the definition of ICT services should be understood in a broad manner to the extent that such services encompass digital and data services provided through ICT systems on an ongoing basis. Therefore, financial entities are responsible for undertaking an assessment on this basis to determine whether the services they rely on are ICT services, as defined under Article 3(21) DORA. Such assessment should be performed taking into account the clarifications from DORA Recital (63), which specifies that DORA should cover a wide range of ICT third-party service providers, including financial entities providing ICT services to other financial entities, and without prejudice to sectoral regulations applicable on regulated financial services.<\/p>\n<p>Financial services may entail an ICT component. In the case that financial entities provide ICT services to other financial entities in connection to their financial services, the receiving financial entities should assess whether i) the services constitute an ICT service under DORA, and ii) whether the providing financial entities and the financial services they provide are regulated under Union law or any national legislation of a Member State or of a third country. In case both tests are positive, then the related ICT service should be considered to predominantly be a financial service and should not be treated as an ICT service within the meaning of DORA Article 3(21).<\/p>\n<p>In case the service is provided by a regulated financial entity providing regulated financial services but is unrelated or is independent from such regulated financial services, the service should be considered as an ICT service under Article 3(21) DORA.&nbsp;<\/p>\n<p>The same rationale applies to ancillary services provided by an entity, depending on whether such ancillary services are regulated financial services or a service inseparable from, indivisible from, preparatory or necessary for the provision of a regulated financial service, and are not provided in a standalone manner.&nbsp;<\/p>\n<p>The clarification about the difference between financial services and ICT services is without prejudice to the requirements applicable to financial entities under DORA, other than the requirements related to ICT third-party risk management.<\/p>\n<p><em>Disclaimer provided by the European Commission:<\/em><\/p>\n<p><em>The answers clarify provisions already contained in the applicable legislation. They do not extend in any way the rights and obligations deriving from such legislation nor do they introduce any additional requirements for the concerned operators and competent authorities. The answers are merely intended to assist natural or legal persons, including competent authorities and Union institutions and bodies in clarifying the application or implementation of the relevant legal provisions. Only the Court of Justice of the European Union is competent to authoritatively interpret Union law. The views expressed in the internal Commission Decision cannot prejudge the position that the European Commission might take before the Union and national courts.<\/em><\/p>    <\/div>  <\/div><\/div><div class=\"card\">  <div class=\"card-header\" id=\"heading-6a39a69ae6cb9\">    <h3 class=\"mb-0\">      <button class=\"btn btn-link btn-block text-left p-0 d-flex align-items-center justify-content-between\" type=\"button\" data-toggle=\"collapse\" data-target=\"#collapse-heading-6a39a69ae6cb9\" aria-expanded=\"false\" aria-controls=\"collapse-heading-6a39a69ae6cb9\">        <span>To what extent are sub-providers to be taken into account in the risk assessment?<\/span>        <i class=\"fa-solid fa-chevron-down text-primary\" aria-hidden=\"true\"><\/i>      <\/button>    <\/h3>  <\/div>  <div id=\"collapse-heading-6a39a69ae6cb9\" class=\"collapse\" aria-labelledby=\"heading-6a39a69ae6cb9\">    <div class=\"card-body\"><p>The assessment and the depth of the assessment is required to take place in a risk-based approach and from the point of view of proportionality. The Regulatory Technical Standards to specify the elements which a financial entity needs to determine and assess when subcontracting ICT services supporting critical or important functions (Article 30(5) DORA) contains more detailed rules.<\/p>    <\/div>  <\/div><\/div><div class=\"card\">  <div class=\"card-header\" id=\"heading-6a39a69ae6d73\">    <h3 class=\"mb-0\">      <button class=\"btn btn-link btn-block text-left p-0 d-flex align-items-center justify-content-between\" type=\"button\" data-toggle=\"collapse\" data-target=\"#collapse-heading-6a39a69ae6d73\" aria-expanded=\"false\" aria-controls=\"collapse-heading-6a39a69ae6d73\">        <span>Can industry certifications (eg ISO 27001) be used as a substitute for a detailed analysis when assessing the service provider? To what extent is the EU Common Cybersecurity Certification (EU-CC) considered as a &ldquo;certification mark&rdquo; that is relevant when evaluating service providers?<\/span>        <i class=\"fa-solid fa-chevron-down text-primary\" aria-hidden=\"true\"><\/i>      <\/button>    <\/h3>  <\/div>  <div id=\"collapse-heading-6a39a69ae6d73\" class=\"collapse\" aria-labelledby=\"heading-6a39a69ae6d73\">    <div class=\"card-body\"><p>While certifications may be taken into account when assessing the suitability of a service provider as a source of information, they are not however a substitute for a service provider assessment.<\/p>    <\/div>  <\/div><\/div><div class=\"card\">  <div class=\"card-header\" id=\"heading-6a39a69ae6e09\">    <h3 class=\"mb-0\">      <button class=\"btn btn-link btn-block text-left p-0 d-flex align-items-center justify-content-between\" type=\"button\" data-toggle=\"collapse\" data-target=\"#collapse-heading-6a39a69ae6e09\" aria-expanded=\"false\" aria-controls=\"collapse-heading-6a39a69ae6e09\">        <span>From when should banks no longer rely on industry certifications from service providers?<\/span>        <i class=\"fa-solid fa-chevron-down text-primary\" aria-hidden=\"true\"><\/i>      <\/button>    <\/h3>  <\/div>  <div id=\"collapse-heading-6a39a69ae6e09\" class=\"collapse\" aria-labelledby=\"heading-6a39a69ae6e09\">    <div class=\"card-body\"><p>As stated in the response to the previous question, a certification may not be considered as a substitute for assessing the service provider, and similar a certification may not replace the ongoing (re-)auditing of the service provider. The frequency of ongoing reviews of service providers depends on their criticality and therefore is to be assessed on a case-by-case basis.<\/p>    <\/div>  <\/div><\/div><p class=\"wp-block-paragraph\">The contents on this website as well as hyperlinks to third party websites serve the purpose of providing general and non-binding information. These &ldquo;Questions and Answers&rdquo; do not constitute the FMA&rsquo;s binding interpretation and in particular do not constitute interpretation within the scope of the question and answer processes (Q&amp;As) of the three European Supervisory Authorities (EBA &ndash; European Banking Authority, ESMA &ndash; European Securities and Markets Authority, and EIOPA &ndash; European Insurance and Occupational Pensions Authority). All information on this website is provided without any guarantee, especially with regard to its up-to-dateness, completeness and correctness, and the FMA, including its employees or the persons responsible for this website, assume no liability whatsoever for the content; in addition, the FMA neither guarantees nor assumes liability for the use of hyperlinks or content that can be accessed via them.<\/p><h2 class=\"wp-block-heading\">Legal bases<\/h2><p class=\"wp-block-paragraph\">Information regarding the legal bases for DORA can be found on the FMA&rsquo;s <a href=\"https:\/\/fma.gv.at\/dora-digitale-operationale-resilienz-im-finanzsektor\/#dora-law\" target=\"_blank\" rel=\"noreferrer noopener\">&ldquo;<\/a><a href=\"https:\/\/www.fma.gv.at\/en\/cross-sectoral-topics\/dora\/#dora-law\" target=\"_blank\" rel=\"noreferrer noopener\">DORA &ndash; Digital Operational Resilience in the Financial Sector&rdquo;<\/a> web page.<\/p><section class=\"page-teaser\"><div class=\"container\"><div class=\"row\"><div class=\"col-12 custom-height\"><h2>Further Information about DORA<\/h2><hr><\/div><\/div><div class=\"row\"><div class=\"mb-4 col-lg-4\"><div class=\"inner\"><div class=\"content-text d-flex flex-column\"><div class=\"img-wrap\"><img loading=\"lazy\" decoding=\"async\" width=\"1320\" height=\"440\" src=\"https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Header-DORA-Webseite-1320x440-DORA-Landingpage.jpg\" class=\"attachment-full size-full wp-post-image\" alt=\"\" srcset=\"https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Header-DORA-Webseite-1320x440-DORA-Landingpage.jpg 1320w, https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Header-DORA-Webseite-1320x440-DORA-Landingpage-320x107.jpg 320w, https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Header-DORA-Webseite-1320x440-DORA-Landingpage-640x213.jpg 640w\" sizes=\"auto, (max-width: 1320px) 100vw, 1320px\"><\/div><h3><a class=\"stretched-link\" href=\"https:\/\/www.fma.gv.at\/en\/cross-sectoral-topics\/dora\/\">DORA &ndash; Digital operational resilience in the financial sector<\/a><\/h3><\/div><hr><\/div><\/div><div class=\"mb-4 col-lg-4\"><div class=\"inner\"><div class=\"content-text d-flex flex-column\"><div class=\"img-wrap\"><img loading=\"lazy\" decoding=\"async\" width=\"1700\" height=\"716\" src=\"https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Cover-DORA-Webseite-1700x716-DORA-IKT-Risikomanagement-2.jpg\" class=\"attachment-full size-full wp-post-image\" alt=\"\" srcset=\"https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Cover-DORA-Webseite-1700x716-DORA-IKT-Risikomanagement-2.jpg 1700w, https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Cover-DORA-Webseite-1700x716-DORA-IKT-Risikomanagement-2-320x135.jpg 320w, https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Cover-DORA-Webseite-1700x716-DORA-IKT-Risikomanagement-2-640x270.jpg 640w, https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Cover-DORA-Webseite-1700x716-DORA-IKT-Risikomanagement-2-1536x647.jpg 1536w\" sizes=\"auto, (max-width: 1700px) 100vw, 1700px\"><\/div><h3><a class=\"stretched-link\" href=\"https:\/\/www.fma.gv.at\/en\/cross-sectoral-topics\/dora\/dora-ict-risk-management\/\">DORA &ndash; ICT Risk Management<\/a><\/h3><\/div><hr><\/div><\/div><div class=\"mb-4 col-lg-4\"><div class=\"inner\"><div class=\"content-text d-flex flex-column\"><div class=\"img-wrap\"><img loading=\"lazy\" decoding=\"async\" width=\"1320\" height=\"440\" src=\"https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Header-DORA-Webseite-1320x440-DORA-IKT-bezogene-Vorfaelle-2.jpg\" class=\"attachment-full size-full wp-post-image\" alt=\"\" srcset=\"https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Header-DORA-Webseite-1320x440-DORA-IKT-bezogene-Vorfaelle-2.jpg 1320w, https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Header-DORA-Webseite-1320x440-DORA-IKT-bezogene-Vorfaelle-2-320x107.jpg 320w, https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Header-DORA-Webseite-1320x440-DORA-IKT-bezogene-Vorfaelle-2-640x213.jpg 640w\" sizes=\"auto, (max-width: 1320px) 100vw, 1320px\"><\/div><h3><a class=\"stretched-link\" href=\"https:\/\/www.fma.gv.at\/en\/cross-sectoral-topics\/dora\/dora-ict-related-incidents\/\">DORA &ndash; ICT-related incidents<\/a><\/h3><\/div><hr><\/div><\/div><div class=\"mb-4 col-lg-4\"><div class=\"inner\"><div class=\"content-text d-flex flex-column\"><div class=\"img-wrap\"><img loading=\"lazy\" decoding=\"async\" width=\"1320\" height=\"440\" src=\"https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Header-DORA-Webseite-1320x440-DORA-Testen-der-digitalen-operationalen-Resilienz-3.jpg\" class=\"attachment-full size-full wp-post-image\" alt=\"\" srcset=\"https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Header-DORA-Webseite-1320x440-DORA-Testen-der-digitalen-operationalen-Resilienz-3.jpg 1320w, https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Header-DORA-Webseite-1320x440-DORA-Testen-der-digitalen-operationalen-Resilienz-3-320x107.jpg 320w, https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Header-DORA-Webseite-1320x440-DORA-Testen-der-digitalen-operationalen-Resilienz-3-640x213.jpg 640w\" sizes=\"auto, (max-width: 1320px) 100vw, 1320px\"><\/div><h3><a class=\"stretched-link\" href=\"https:\/\/www.fma.gv.at\/en\/cross-sectoral-topics\/dora\/dora-digital-operational-resilience-testing\/\">DORA &ndash; Digital operational resilience testing<\/a><\/h3><\/div><hr><\/div><\/div><div class=\"mb-4 col-lg-4\"><div class=\"inner\"><div class=\"content-text d-flex flex-column\"><div class=\"img-wrap\"><img loading=\"lazy\" decoding=\"async\" width=\"1320\" height=\"440\" src=\"https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Header-DORA-Webseite-1320x440-DORA-Ueberwachungsrahmen-kritischer-IKT-Drittdienstleister-2.jpg\" class=\"attachment-full size-full wp-post-image\" alt=\"\" srcset=\"https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Header-DORA-Webseite-1320x440-DORA-Ueberwachungsrahmen-kritischer-IKT-Drittdienstleister-2.jpg 1320w, https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Header-DORA-Webseite-1320x440-DORA-Ueberwachungsrahmen-kritischer-IKT-Drittdienstleister-2-320x107.jpg 320w, https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Header-DORA-Webseite-1320x440-DORA-Ueberwachungsrahmen-kritischer-IKT-Drittdienstleister-2-640x213.jpg 640w\" sizes=\"auto, (max-width: 1320px) 100vw, 1320px\"><\/div><h3><a class=\"stretched-link\" href=\"https:\/\/www.fma.gv.at\/en\/cross-sectoral-topics\/dora\/dora-oversight-framework-of-critical-ict-third-party-service-providers\/\">DORA &ndash; Oversight framework of critical ICT third-party service providers<\/a><\/h3><\/div><hr><\/div><\/div><div class=\"mb-4 col-lg-4\"><div class=\"inner\"><div class=\"content-text d-flex flex-column\"><div class=\"img-wrap\"><img loading=\"lazy\" decoding=\"async\" width=\"1320\" height=\"440\" src=\"https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Header-DORA-Webseite-1320x440-DORA-Informationsaustausch-2.jpg\" class=\"attachment-full size-full wp-post-image\" alt=\"\" srcset=\"https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Header-DORA-Webseite-1320x440-DORA-Informationsaustausch-2.jpg 1320w, https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Header-DORA-Webseite-1320x440-DORA-Informationsaustausch-2-320x107.jpg 320w, https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Header-DORA-Webseite-1320x440-DORA-Informationsaustausch-2-640x213.jpg 640w\" sizes=\"auto, (max-width: 1320px) 100vw, 1320px\"><\/div><h3><a class=\"stretched-link\" href=\"https:\/\/www.fma.gv.at\/en\/cross-sectoral-topics\/dora\/dora-exchange-of-information-and-contingency-exercises\/\">DORA &ndash; Exchange of information and contingency exercises<\/a><\/h3><\/div><hr><\/div><\/div><\/div><\/div><\/section>\n","protected":false},"excerpt":{"rendered":"<p>Financial entities manage the third-party risk of information and communication technologies (ICT third-party risk) across the entire life cycle. The &#8230;<\/p>\n","protected":false},"author":20,"featured_media":50885,"parent":52247,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"landing-page.php","meta":{"inline_featured_image":false,"footnotes":""},"class_list":["post-158458","page","type-page","status-publish","has-post-thumbnail","hentry"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>DORA \u2013 Managing of ICT third-party risk - FMA \u00d6sterreich<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.fma.gv.at\/en\/cross-sectoral-topics\/dora\/dora-managing-of-ict-third-party-risk\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"DORA \u2013 Managing of ICT third-party risk - FMA \u00d6sterreich\" \/>\n<meta property=\"og:description\" content=\"Financial entities manage the third-party risk of information and communication technologies (ICT third-party risk) across the entire life cycle. The ...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.fma.gv.at\/en\/cross-sectoral-topics\/dora\/dora-managing-of-ict-third-party-risk\/\" \/>\n<meta property=\"og:site_name\" content=\"FMA \u00d6sterreich\" \/>\n<meta property=\"article:modified_time\" content=\"2026-02-13T12:51:15+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Header-DORA-Webseite-1320x440-DORA-Management-des-IKT-Drittparteienrisikos.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1320\" \/>\n\t<meta property=\"og:image:height\" content=\"440\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:site\" content=\"@FMA_AT\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.fma.gv.at\\\/en\\\/cross-sectoral-topics\\\/dora\\\/dora-managing-of-ict-third-party-risk\\\/\",\"url\":\"https:\\\/\\\/www.fma.gv.at\\\/en\\\/cross-sectoral-topics\\\/dora\\\/dora-managing-of-ict-third-party-risk\\\/\",\"name\":\"DORA \u2013 Managing of ICT third-party risk - FMA \u00d6sterreich\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.fma.gv.at\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.fma.gv.at\\\/en\\\/cross-sectoral-topics\\\/dora\\\/dora-managing-of-ict-third-party-risk\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.fma.gv.at\\\/en\\\/cross-sectoral-topics\\\/dora\\\/dora-managing-of-ict-third-party-risk\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.fma.gv.at\\\/wp-content\\\/uploads\\\/2024\\\/07\\\/Header-DORA-Webseite-1320x440-DORA-Management-des-IKT-Drittparteienrisikos.jpg\",\"datePublished\":\"2024-07-23T13:09:16+00:00\",\"dateModified\":\"2026-02-13T12:51:15+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.fma.gv.at\\\/en\\\/cross-sectoral-topics\\\/dora\\\/dora-managing-of-ict-third-party-risk\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.fma.gv.at\\\/en\\\/cross-sectoral-topics\\\/dora\\\/dora-managing-of-ict-third-party-risk\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.fma.gv.at\\\/en\\\/cross-sectoral-topics\\\/dora\\\/dora-managing-of-ict-third-party-risk\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.fma.gv.at\\\/wp-content\\\/uploads\\\/2024\\\/07\\\/Header-DORA-Webseite-1320x440-DORA-Management-des-IKT-Drittparteienrisikos.jpg\",\"contentUrl\":\"https:\\\/\\\/www.fma.gv.at\\\/wp-content\\\/uploads\\\/2024\\\/07\\\/Header-DORA-Webseite-1320x440-DORA-Management-des-IKT-Drittparteienrisikos.jpg\",\"width\":1320,\"height\":440},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.fma.gv.at\\\/en\\\/cross-sectoral-topics\\\/dora\\\/dora-managing-of-ict-third-party-risk\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.fma.gv.at\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Cross-sectoral topics\",\"item\":\"https:\\\/\\\/www.fma.gv.at\\\/en\\\/cross-sectoral-topics\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"DORA \u2013 Digital operational resilience in the financial sector\",\"item\":\"https:\\\/\\\/www.fma.gv.at\\\/en\\\/cross-sectoral-topics\\\/dora\\\/\"},{\"@type\":\"ListItem\",\"position\":4,\"name\":\"DORA \u2013 Managing of ICT third-party risk\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.fma.gv.at\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/www.fma.gv.at\\\/en\\\/\",\"name\":\"FMA \u00d6sterreich\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.fma.gv.at\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.fma.gv.at\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.fma.gv.at\\\/en\\\/#organization\",\"name\":\"FMA - Finanzmarktaufsicht\",\"url\":\"https:\\\/\\\/www.fma.gv.at\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.fma.gv.at\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.fma.gv.at\\\/wp-content\\\/uploads\\\/2017\\\/05\\\/FMA_Logo_Twitter_400x400.png\",\"contentUrl\":\"https:\\\/\\\/www.fma.gv.at\\\/wp-content\\\/uploads\\\/2017\\\/05\\\/FMA_Logo_Twitter_400x400.png\",\"width\":400,\"height\":400,\"caption\":\"FMA - Finanzmarktaufsicht\"},\"image\":{\"@id\":\"https:\\\/\\\/www.fma.gv.at\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/FMA_AT\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"DORA \u2013 Managing of ICT third-party risk - FMA \u00d6sterreich","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.fma.gv.at\/en\/cross-sectoral-topics\/dora\/dora-managing-of-ict-third-party-risk\/","og_locale":"en_US","og_type":"article","og_title":"DORA \u2013 Managing of ICT third-party risk - FMA \u00d6sterreich","og_description":"Financial entities manage the third-party risk of information and communication technologies (ICT third-party risk) across the entire life cycle. The ...","og_url":"https:\/\/www.fma.gv.at\/en\/cross-sectoral-topics\/dora\/dora-managing-of-ict-third-party-risk\/","og_site_name":"FMA \u00d6sterreich","article_modified_time":"2026-02-13T12:51:15+00:00","og_image":[{"width":1320,"height":440,"url":"https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Header-DORA-Webseite-1320x440-DORA-Management-des-IKT-Drittparteienrisikos.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_site":"@FMA_AT","twitter_misc":{"Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.fma.gv.at\/en\/cross-sectoral-topics\/dora\/dora-managing-of-ict-third-party-risk\/","url":"https:\/\/www.fma.gv.at\/en\/cross-sectoral-topics\/dora\/dora-managing-of-ict-third-party-risk\/","name":"DORA \u2013 Managing of ICT third-party risk - FMA \u00d6sterreich","isPartOf":{"@id":"https:\/\/www.fma.gv.at\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.fma.gv.at\/en\/cross-sectoral-topics\/dora\/dora-managing-of-ict-third-party-risk\/#primaryimage"},"image":{"@id":"https:\/\/www.fma.gv.at\/en\/cross-sectoral-topics\/dora\/dora-managing-of-ict-third-party-risk\/#primaryimage"},"thumbnailUrl":"https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Header-DORA-Webseite-1320x440-DORA-Management-des-IKT-Drittparteienrisikos.jpg","datePublished":"2024-07-23T13:09:16+00:00","dateModified":"2026-02-13T12:51:15+00:00","breadcrumb":{"@id":"https:\/\/www.fma.gv.at\/en\/cross-sectoral-topics\/dora\/dora-managing-of-ict-third-party-risk\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.fma.gv.at\/en\/cross-sectoral-topics\/dora\/dora-managing-of-ict-third-party-risk\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.fma.gv.at\/en\/cross-sectoral-topics\/dora\/dora-managing-of-ict-third-party-risk\/#primaryimage","url":"https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Header-DORA-Webseite-1320x440-DORA-Management-des-IKT-Drittparteienrisikos.jpg","contentUrl":"https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Header-DORA-Webseite-1320x440-DORA-Management-des-IKT-Drittparteienrisikos.jpg","width":1320,"height":440},{"@type":"BreadcrumbList","@id":"https:\/\/www.fma.gv.at\/en\/cross-sectoral-topics\/dora\/dora-managing-of-ict-third-party-risk\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.fma.gv.at\/en\/"},{"@type":"ListItem","position":2,"name":"Cross-sectoral topics","item":"https:\/\/www.fma.gv.at\/en\/cross-sectoral-topics\/"},{"@type":"ListItem","position":3,"name":"DORA \u2013 Digital operational resilience in the financial sector","item":"https:\/\/www.fma.gv.at\/en\/cross-sectoral-topics\/dora\/"},{"@type":"ListItem","position":4,"name":"DORA \u2013 Managing of ICT third-party risk"}]},{"@type":"WebSite","@id":"https:\/\/www.fma.gv.at\/en\/#website","url":"https:\/\/www.fma.gv.at\/en\/","name":"FMA \u00d6sterreich","description":"","publisher":{"@id":"https:\/\/www.fma.gv.at\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.fma.gv.at\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.fma.gv.at\/en\/#organization","name":"FMA - Finanzmarktaufsicht","url":"https:\/\/www.fma.gv.at\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.fma.gv.at\/en\/#\/schema\/logo\/image\/","url":"https:\/\/www.fma.gv.at\/wp-content\/uploads\/2017\/05\/FMA_Logo_Twitter_400x400.png","contentUrl":"https:\/\/www.fma.gv.at\/wp-content\/uploads\/2017\/05\/FMA_Logo_Twitter_400x400.png","width":400,"height":400,"caption":"FMA - Finanzmarktaufsicht"},"image":{"@id":"https:\/\/www.fma.gv.at\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/FMA_AT"]}]}},"toolset-meta":[],"publishpress_future_action":{"enabled":false,"date":"2026-06-29 21:18:19","action":"change-status","newStatus":"draft","terms":[],"taxonomy":"translation_priority","extraData":[]},"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.fma.gv.at\/en\/wp-json\/wp\/v2\/pages\/158458","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.fma.gv.at\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.fma.gv.at\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.fma.gv.at\/en\/wp-json\/wp\/v2\/users\/20"}],"replies":[{"embeddable":true,"href":"https:\/\/www.fma.gv.at\/en\/wp-json\/wp\/v2\/comments?post=158458"}],"version-history":[{"count":7,"href":"https:\/\/www.fma.gv.at\/en\/wp-json\/wp\/v2\/pages\/158458\/revisions"}],"predecessor-version":[{"id":28730866,"href":"https:\/\/www.fma.gv.at\/en\/wp-json\/wp\/v2\/pages\/158458\/revisions\/28730866"}],"up":[{"embeddable":true,"href":"https:\/\/www.fma.gv.at\/en\/wp-json\/wp\/v2\/pages\/52247"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.fma.gv.at\/en\/wp-json\/wp\/v2\/media\/50885"}],"wp:attachment":[{"href":"https:\/\/www.fma.gv.at\/en\/wp-json\/wp\/v2\/media?parent=158458"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}